CVE-2018-0488: Critical severity Arm mbed TLS vulnerability
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0488?
CVE-2018-0488 is a vulnerability in ARM mbed TLS before version 1.3.22, 2.1.10, and 2.7.0 that allows remote attackers to execute arbitrary code or cause a denial of service.
What is the severity of CVE-2018-0488?
The severity of CVE-2018-0488 is critical with a CVSS score of 9.8.
How can an attacker exploit CVE-2018-0488?
An attacker can exploit CVE-2018-0488 by sending a crafted application packet within a TLS or DTLS session.
Which versions of ARM mbed TLS are affected by CVE-2018-0488?
Versions before 1.3.22, 2.1.10, and 2.7.0 of ARM mbed TLS are affected by CVE-2018-0488.
What is the remedy for CVE-2018-0488?
The remedy for CVE-2018-0488 is to update to the recommended versions of the affected software.